<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic C&amp;amp;C threat from outside 45.9.148.91 similar Shodan Malware hunter ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/c-amp-c-threat-from-outside-45-9-148-91-similar-shodan-malware/m-p/336604#M84800</link>
    <description>&lt;P&gt;Hi Live community,&lt;/P&gt;&lt;P&gt;recently when investigating a false positive C&amp;amp;C threat blocked from "shodan malware hunter" I was pleased to see others had posted into this community about this. In the past 24 hrs we have 2 SIEM alerts for C&amp;amp;C outside to publically presented hosts from 45.9.148.91.&amp;nbsp;Anyone else seeing this behaviour ?&lt;/P&gt;&lt;P&gt;PAN did reset both but I am considering a block rule, but of course the src IP could change at any time.&lt;/P&gt;&lt;P&gt;IP is on some blacklists:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;xbl.spamhaus.org&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;has&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;blacklisted this IP.&lt;/SPAN&gt;&lt;BR /&gt;&lt;STRONG&gt;zen.spamhaus.org&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;has&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;blacklisted this IP.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;and appears to slowly, be carrying out reconnaissance on our public IP space.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;KR,&lt;/P&gt;&lt;P&gt;Lee&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 04 Jul 2020 16:15:55 GMT</pubDate>
    <dc:creator>LeeFrancis2</dc:creator>
    <dc:date>2020-07-04T16:15:55Z</dc:date>
    <item>
      <title>C&amp;C threat from outside 45.9.148.91 similar Shodan Malware hunter ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/c-amp-c-threat-from-outside-45-9-148-91-similar-shodan-malware/m-p/336604#M84800</link>
      <description>&lt;P&gt;Hi Live community,&lt;/P&gt;&lt;P&gt;recently when investigating a false positive C&amp;amp;C threat blocked from "shodan malware hunter" I was pleased to see others had posted into this community about this. In the past 24 hrs we have 2 SIEM alerts for C&amp;amp;C outside to publically presented hosts from 45.9.148.91.&amp;nbsp;Anyone else seeing this behaviour ?&lt;/P&gt;&lt;P&gt;PAN did reset both but I am considering a block rule, but of course the src IP could change at any time.&lt;/P&gt;&lt;P&gt;IP is on some blacklists:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;xbl.spamhaus.org&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;has&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;blacklisted this IP.&lt;/SPAN&gt;&lt;BR /&gt;&lt;STRONG&gt;zen.spamhaus.org&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;has&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;blacklisted this IP.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;and appears to slowly, be carrying out reconnaissance on our public IP space.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;KR,&lt;/P&gt;&lt;P&gt;Lee&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Jul 2020 16:15:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/c-amp-c-threat-from-outside-45-9-148-91-similar-shodan-malware/m-p/336604#M84800</guid>
      <dc:creator>LeeFrancis2</dc:creator>
      <dc:date>2020-07-04T16:15:55Z</dc:date>
    </item>
    <item>
      <title>Re: C&amp;C threat from outside 45.9.148.91 similar Shodan Malware hunter ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/c-amp-c-threat-from-outside-45-9-148-91-similar-shodan-malware/m-p/336761#M84874</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I try to keep things dynamic and self learning. Meaning I stay away from IP's since they change too fast. Since a EBL has it, i say let it run with it. Also I would enable sending telemetry back to Palo Alto so they can update their definitions so we dont have to :).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope that makes sense.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 20:53:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/c-amp-c-threat-from-outside-45-9-148-91-similar-shodan-malware/m-p/336761#M84874</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-07-06T20:53:44Z</dc:date>
    </item>
  </channel>
</rss>

